Talk to an engineer

Category F · 5 services

Cybersecurity & Compliance

Security designed into the architecture, monitored continuously, and evidenced for audit.

Cabinets of a national laboratory supercomputer

Security added at the edge of a system protects the edge of a system. We design it into the architecture: workload identity instead of long-lived secrets, key custody with rotation that has been rehearsed, policy enforced at every hop rather than only at the perimeter, and evidence collected automatically because an auditor will ask for it and a spreadsheet is not an answer.

What we build

F.1

Security Architecture & Zero Trust

Identity, key custody, and zero-trust paths through the whole stack

Security designed into the architecture rather than added at its edge. Workload identity and short-lived credentials, key custody in HSMs and KMS with rotation and recovery documented and rehearsed, end-to-end encryption and tokenisation for regulated data, zero-trust paths with policy enforced at every hop, supply-chain integrity through signed builds and software bills of materials, and threat models written against the system as it is actually deployed.

  • mTLS
  • SPIFFE
  • HSM and KMS
  • Zero trust
  • SBOM
  • Sigstore
What we build
F.2

Managed Detection & Response

Someone watching, with a playbook, at three in the morning

Continuous monitoring and response across endpoints, identity, cloud, and network. Log and telemetry collection into a SIEM with detections written for your environment rather than a vendor default, endpoint detection and response, identity threat detection, threat intelligence enrichment, triage and containment playbooks with automation where it is safe, and an incident process that ends in a written cause and a change.

  • SIEM
  • EDR and XDR
  • MITRE ATT&CK
  • SOAR
  • Threat hunting
What we build
F.3

Penetration Testing & Vulnerability Management

Findings with a proof of exploit and a fix, not a scanner export

Authorised offensive testing and a vulnerability programme that actually closes things. Web, mobile, API, cloud configuration, network, and internal testing, source-assisted review where it finds more, a proof of exploit for every material finding, a remediation plan in the order we would actually fix it, retesting after the fix, and continuous scanning wired into the pipeline so the next release does not reintroduce what you just closed.

  • OWASP Top 10
  • OWASP ASVS
  • PTES
  • CVSS
  • SAST and DAST
What we build
F.4

Identity & Access Management

The right people, the right systems, and a leaver who is really gone

Identity as the control plane. Single sign-on and multi-factor authentication across the estate, directory consolidation, automated joiner, mover, and leaver provisioning through SCIM, role and attribute-based access models that a manager can actually approve, privileged access management with session recording, access reviews that run on a schedule, and passwordless where the estate supports it.

  • SAML
  • OIDC
  • SCIM
  • FIDO2 and passkeys
  • PAM
  • Access reviews
What we build
F.5

Compliance, Audit & Risk Management

Controls mapped to the code path that implements them

Getting to a certification and staying there. Gap assessment against ISO 27001, SOC 2, IEC 62443, PCI DSS, HIPAA, GDPR, and the DPDP Act, controls mapped to the architecture and to the code path that implements them, policy written to be followed rather than filed, evidence collection automated wherever the system can produce it, internal audit and readiness review, and support through the external audit itself.

  • ISO 27001
  • SOC 2
  • PCI DSS
  • HIPAA
  • GDPR
  • DPDP Act
  • IEC 62443
What we build

How it connects

Inside cybersecurity.

The systems in this area, and what each one hands to the next.

01

Security Architecture

Security designed into the architecture rather than added at its edge.

What we build
02

Managed Detection & Response

Continuous monitoring and response across endpoints, identity, cloud, and network.

What we build
03

Penetration Testing

Authorised offensive testing and a vulnerability programme that actually closes things.

What we build
04

Identity & Access

Identity as the control plane.

What we build
05

Compliance & Risk

Getting to a certification and staying there.

What we build

Bring us the whole problem.

Tell us where the work is stuck, whether that is a model that never reached production, an application nobody can change, a data platform nobody trusts, or a plant the business cannot see. An engineer replies with a first read, not a sales deck.